{"id":4868,"date":"2025-06-26T03:04:20","date_gmt":"2025-06-26T03:04:20","guid":{"rendered":"https:\/\/mailitics.com\/index.php\/2025\/06\/26\/modern-cisos-must-throw-out-the-traditional-cybersecurity-playbook-174241347\/"},"modified":"2025-06-26T03:04:20","modified_gmt":"2025-06-26T03:04:20","slug":"modern-cisos-must-throw-out-the-traditional-cybersecurity-playbook-174241347","status":"publish","type":"post","link":"https:\/\/mailitics.com\/index.php\/2025\/06\/26\/modern-cisos-must-throw-out-the-traditional-cybersecurity-playbook-174241347\/","title":{"rendered":"Modern CISOs must throw out the traditional cybersecurity playbook"},"content":{"rendered":"<p>    Modern CISOs must throw out the traditional cybersecurity playbook<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<img data-recalc-dims=\"1\" decoding=\"async\" class=\"img-responsive\" src=\"https:\/\/i0.wp.com\/d1v1e13ebw3o15.cloudfront.net\/data\/88966\/pool_and_spa_logo\/..jpg?ssl=1\"> <\/p>\n<p>The traditional approach to cybersecurity is no longer sufficient in today\u2019s evolving business environment, and CISOs are now expected to be much more than technical experts.<\/p>\n<p>While keeping pace with evolving cyberthreats remains essential, the primary imperative for CISOs should be to align the security agenda with business value, communicate risks in the language of the boardroom, and foster a culture where everyone understands their role in protecting the organisation. Ultimately, the evolution of the CISO role is driven by the need to align security initiatives with business objectives and to enable the entire organisation to operate securely.<\/p>\n<p>According to PwC\u2019s <a href=\"https:\/\/www.pwc.com\/us\/en\/executive-leadership-hub\/ciso.html\" target=\"_blank\" rel=\"noopener\">2025 Global Digital Trust Insights<\/a>, fewer than half of CISOs are involved in strategic investment planning, board reporting, or technology deployment decisions, leading to a dangerous gap in organisational oversight.<\/p>\n<p>To close this gap, CISOs must take an agile and collaborative approach by building cross-functional relationships with finance, legal and C-suite, integrating resilience and security by designing to support innovation, transformation and growth while keeping stakeholders informed on the latest risks.<\/p>\n<h4>Addressing evolving threats<\/h4>\n<p>With cyberthreats growing more sophisticated, particularly with the rise of AI-assisted attacks, security leaders must ask questions to understand how cyberthreats can impact the business. Four questions to begin with should be:<\/p>\n<ol>\n<li>Which business processes, systems and applications are most critical and, if disrupted, could impact revenue streams?<\/li>\n<li>Which business risks are most important to mitigate that could lead to reputational or operational harm?<\/li>\n<li>What data, if compromised or leaked, would erode trust and reputation?<\/li>\n<li>Which third-party relationships could become your biggest vulnerability?<\/li>\n<\/ol>\n<p>Too often, organisations struggle to answer these questions clearly, despite investing millions in cybersecurity tools.<\/p>\n<p>CISOs should focus on protecting the organisation\u2019s most essential business processes, systems, applications and data in order to reduce the likelihood of data breaches that could result in revenue loss, operational disruption, regulatory consequences and damage to reputation.<\/p>\n<p>To do so, organisations must adopt a risk-based approach that evaluates and quantifies business impact based on potential loss events. It is recommended that organisations immediately take three approaches as follows:<\/p>\n<ol>\n<li>\n<strong>Quantify cyber risks in business terms:<\/strong> Assess and determine the financial and operational exposure of potential cyber incidents, which may lead to lost revenue, regulatory fines, or customer attrition due to potential data breaches.<\/li>\n<li>\n<strong>Conduct business-focused risk assessments:<\/strong> Partner with business leaders to solicit and identify key business risks, key threats that could harm the business, and business information assets and processes considered critical to the organisation. This ensures that it is taking a prioritised approach to safeguarding what matters the most in order to allocate the adequate resources and investments required.<\/li>\n<li>\n<strong>Align security with business strategy:<\/strong> Align and prioritise security investments and projects in the context of supporting business growth, compliance and resilience. This ensures cybersecurity is acting as a business enabler rather than a cost centre.<\/li>\n<\/ol>\n<h4>Embracing AI to augment and scale against cyberthreats<\/h4>\n<p>When discussing the evolving role of a CISO, I would be remiss not to mention how drastically AI is helping to accelerate this evolution.<\/p>\n<p>AI systems can analyse vast amounts of data in real time, identifying potential threats with speed and accuracy. But AI\u2019s capabilities don\u2019t stop at detection: when it comes to incident response, AI is proving to be a game changer. Imagine a security system that doesn\u2019t just alert you to a threat but takes immediate action to neutralise it. From isolating compromised systems to blocking malicious IP addresses, AI can execute these critical tasks swiftly and without human input, dramatically reducing response times and minimising potential damage.<\/p>\n<p>Recent studies indicate that these AI-driven insider threat behavioural analytics systems can detect up to <a href=\"https:\/\/web.cs.dal.ca\/~lcd\/pubs\/TNSM2021.pdf\" target=\"_blank\" rel=\"noopener\">60% of malicious insiders under a 0.1% investigation budget<\/a> and, in certain cases, achieve full detection within a 5% budget.<\/p>\n<p>At the same time, the AI arms race in cybersecurity isn\u2019t slowing down. Threat actors will continue to get faster, smarter and more targeted. What matters is resilience; the ability to anticipate, analyse, respond and recover from attacks in a timely manner.<\/p>\n<p>Organisations that will thrive are those with security leaders who can evolve with equal agility, building resilient security programs that align with business strategies, protecting critical assets and fostering a culture of shared responsibility.<\/p>\n<h4>The best security controls in the world won\u2019t save you from human nature<\/h4>\n<p>At the end of the day, the best firewall in the world won\u2019t save you from human nature. That\u2019s why CISOs must champion a culture where cybersecurity is everyone\u2019s core responsibility. Cyber training should be reinforced regularly, not just through mandatory modules, but through leadership modelling, clear accountability, and open dialogue across departments. CISOs must build a security-conscious culture that isn\u2019t just about training sessions (though those help). It\u2019s about making security feel like everyone\u2019s responsibility, not just the IT department\u2019s problem.<\/p>\n<table border=\"0\" cellpadding=\"0\" cellspacing=\"0\" style=\"width:100%\">\n<tbody>\n<tr>\n<td style=\"text-align:left; vertical-align:top\">\n<p>In my view, the most forward-thinking organisations are those whose CISOs can \u2018speak two languages\u2019: the technical language of security teams, and the business language of boards and executives.<\/p>\n<p><h8><em>*Aaron Momin is Chief Information Security Officer at <a href=\"https:\/\/www.synechron.com\/en-au\" target=\"_blank\" rel=\"noopener\">Synechron<\/a>.<\/em><\/h8><\/p>\n<\/td>\n<td style=\"text-align:center; vertical-align:top; width:133px\"><img data-recalc-dims=\"1\" decoding=\"async\" alt=\"\" class=\"img-responsive\" src=\"https:\/\/i0.wp.com\/d2emomln4apc0h.cloudfront.net\/assets\/606216\/web_image_article\/Aaron-Momin-cropped.jpg?ssl=1\" style=\"display: block; height: 172px; margin: auto; width: 127px\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><h9>Top image credit: iStock.com\/da-kuk<\/h9><\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><\/p>\n<p> \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/www.technologydecisions.com.au\/content\/security\/article\/modern-cisos-must-throw-out-the-traditional-cybersecurity-playbook-174241347?utm_source=rss\">Go to Technology Decisions<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Modern CISOs must throw out the traditional cybersecurity playbook The traditional approach to cybersecurity is no longer sufficient in today\u2019s evolving business environment, and CISOs are now expected to be much more than technical experts. While keeping pace with evolving cyberthreats remains essential, the primary imperative for CISOs should be to align the security agenda [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[44],"tags":[48],"class_list":["post-4868","post","type-post","status-publish","format-standard","hentry","category-technology-decisions","tag-technology-decisions"],"_links":{"self":[{"href":"https:\/\/mailitics.com\/index.php\/wp-json\/wp\/v2\/posts\/4868"}],"collection":[{"href":"https:\/\/mailitics.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mailitics.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mailitics.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/mailitics.com\/index.php\/wp-json\/wp\/v2\/comments?post=4868"}],"version-history":[{"count":0,"href":"https:\/\/mailitics.com\/index.php\/wp-json\/wp\/v2\/posts\/4868\/revisions"}],"wp:attachment":[{"href":"https:\/\/mailitics.com\/index.php\/wp-json\/wp\/v2\/media?parent=4868"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mailitics.com\/index.php\/wp-json\/wp\/v2\/categories?post=4868"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mailitics.com\/index.php\/wp-json\/wp\/v2\/tags?post=4868"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}